Skip to content
Topic Contested in court

Integrity and Confidentiality Principle

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

While security and beveiliging topics exist, there is no dedicated topic for the integrity and confidentiality principle specifically as articulated in GDPR Article 5(1)(f), which is a distinct foundational principle requiring separate coverage.

387 linked items 6 Laws83 Case Law41 Guidance198 Enforcement31 News

Overview

27 sources · Aug 27, 2026

Legal Framework

The integrity and confidentiality principle is codified in Article 5(1)(f) GDPR, one of the six foundational principles governing all personal data processing. It requires controllers to ensure appropriate security of personal data throughout the processing lifecycle. The provision is deliberately broad, encompassing both technical measures (encryption, access controls, pseudonymisation) and organisational measures (staff training, policies, processor oversight).

"processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures"
— GDPR Art. 5(1)(f)

Recital 75 elaborates the risk landscape that the principle addresses, enumerating physical, material, and non-material damage scenarios — from identity theft and financial loss to discrimination and loss of confidentiality of professionally protected data. Recital 85 connects the principle to breach notification obligations, establishing that failure to maintain appropriate security triggers both the Article 5(1)(f) violation and the Article 33/34 notification duties.

The principle operates alongside, but is distinct from, Article 32 GDPR (security of processing), which provides the operational implementation framework. Article 5(1)(f) sets the principle; Article 32 sets the specific requirements for risk assessment, pseudonymisation, and encryption.

Key Developments

Enforcement authorities across the EU have applied Article 5(1)(f) to both controllers and processors, with particular focus on inadequate technical safeguards. The Croatian DPA sanctioned an IT services provider after a security breach exposed personal data of over 28,000 individuals, finding the processor failed to implement measures proportionate to foreseeable risks:

"The incident occurred because the IT provider had not taken the necessary measures to achieve an adequate level of security in accordance with existing and foreseeable risks."
— Croatian DPA — IT services company

The Italian Garante similarly found against Roma Capitale, where data flows were transmitted through insecure channels and officials could query license plate data en masse without controls. The Garante treated the absence of access restrictions as a direct Article 5(1)(f) failure, not merely an Article 32 deficiency.

Dutch courts have addressed the principle in the context of unauthorised access by employees. In a case against a municipality, the court held that where a controller cannot identify who accessed personal data or for what purpose, the burden falls entirely on the controller:

"Dat het college geen informatie heeft over wie (binnen de gemeente) de persoonsgegevens heeft geraadpleegd en met welk doel is een omstandigheid die volledig voor rekening en risico van het college komt."
— Rechtbank — AVG en verzoek om schadevergoeding

The EDPB's Guidelines 9/2022 clarify that the principle's protective scope extends beyond traditional confidentiality breaches:

"unauthorised or unlawful processing may include disclosure of personal data to (or access by) recipients who are not authorised to receive (or access) the data, or any other form of process"
— EDPB Guidelines 9/2022 §14

Status of the Debate

The integrity and confidentiality principle is actively contested in court. While the textual standard — "appropriate" security — appears settled, its application to specific factual contexts remains in flux. Courts have diverged on the threshold for what constitutes "appropriate" measures, particularly where controllers face resource constraints or where processors rather than controllers are held primarily responsible. The open question is whether courts will adopt a strict risk-proportionality test (where any foreseeable breach demonstrates inadequacy) or a reasonableness standard (where documented risk assessments and layered controls may suffice even when breached). Resolution will likely come from CJEU preliminary references on the interplay between Article 5(1)(f) and Article 32, particularly regarding whether processor failures can constitute controller violations of the principle itself.

Practical Guidance

  • Conduct and document risk assessments mapping to Recital 75 risk categories — discrimination, identity theft, financial loss, reputational damage — to demonstrate that security measures are proportionate to identified risks.

  • Implement layered access controls that log and attribute every instance of personal data access. The Dutch municipality case demonstrates that inability to identify who accessed data constitutes an independent violation.

  • Vet processors against expertise, reliability, and resource criteria before engagement, and contractually mandate security standards. The Croatian enforcement action shows that processor failures expose both the processor and the controller to liability.

  • Secure all data transmission channels — the Roma Capitale decision confirms that transmitting personal data through unencrypted or insecure channels violates Article 5(1)(f) directly, not just Article 32.

  • Integrate breach response with the security principle: maintain incident detection and notification procedures aligned with Recital 85, ensuring that any security failure is assessed for both notification obligations and systemic remediation under the accountability principle.

Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Guidelines 9/2022 personal data breach notification under GDPR Guidelines ·EDPB Guidance EDPB Apr 2023 breach as violation of integrity/confidentiality
why this is here
unauthorised disclosure of, or access to, personal data

The definition of breach directly relates to unauthorised access or disclosure, which is a violation of integrity and confidentiality principles.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Guidance EDPB Oct 2020 Integrity and confidentiality as principles
why this is here
each of the aforementioned principles and the ensuing protection of rights

Integrity and confidentiality are among Article 5 principles, but the document does not specifically single them out.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 2/2023 Technical Scope of Art. 5(3) of ePrivacy Directive Guidelines ·EDPB Guidance EDPB Oct 2024 protecting terminal equipment integrity
why this is here
the ePD protects users’ privacy not only in relation to the confidentiality of their information but also by safeguarding the integrity of the user’s terminal equipment

Mentions integrity but not as a GDPR principle.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 Security and privacy consideration
why this is here
security and privacy of connected vehicles

The document mentions security in the context of related works, but does not specifically address integrity and confidentiality as a principle.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

This is the top of each pile — all 83 Case Law · all 41 Guidance · all 198 Enforcement · all 28 Literature · all 31 News